Crypto Academy Fraud, Cartel Laundering and a Cyberattack on 30 Water Utilities
A fraudulent cryptocurrency academy that preyed on cancer patients and pensioners, a Brazilian drug cartel that laundered billions through crypto brokers, and a cyberattack that knocked out automation at more than 30 water utilities across Minnesota — this week's crypto crime developments span three continents and illustrate how deeply digital assets have become embedded in both financial crime and critical infrastructure attacks.
Ukraine's Fake "Crypto Academy" Stole $1.1 Million From a Thousand Victims
Ukrainian cyber police have dismantled a criminal organisation that posed as the "Ukrainian Financial Academy" to defraud approximately one thousand people out of a combined $1.11 million. Four key suspects, including two organisers, were arrested following searches in the Kharkiv and Dnipropetrovsk regions.
The scheme operated through classic investment fraud mechanics with a cryptocurrency veneer. Fraudsters contacted victims, assessed their financial situations and persuaded them to transfer funds into controlled crypto wallets. A specially created fake trading platform displayed charts showing fabricated "successful trading balances" — giving victims the impression their investments were growing.
In some cases, victims were permitted to withdraw a small amount early in the scheme — a deliberate trust-building tactic designed to encourage larger subsequent deposits. When victims later attempted to withdraw their main funds, withdrawals were blocked. The perpetrators then demanded additional payments framed as fees or contributions to a "reserve fund."
Investigators say the scheme deliberately targeted the most vulnerable. Victims included pensioners, people with disabilities and the seriously ill. One victim undergoing cancer treatment transferred approximately 500,000 hryvnias — funds set aside for medical expenses — to the fraudsters. When victims exhausted their own savings, they were encouraged to take out loans to continue investing.
The operation also harvested positive video testimonials from victims during moments of apparent trading success, which were subsequently used in advertisements to recruit new victims. Those arrested face up to 12 years in prison with asset confiscation.
Brazilian Drug Cartel Laundered Billions Through Crypto Brokers
Brazilian federal police dismantled an international drug syndicate suspected of smuggling at least 6.5 tons of cocaine and laundering proceeds through a sophisticated cryptocurrency infrastructure spanning multiple states.
Raids across São Paulo, Minas Gerais, Santa Catarina and Espírito Santo resulted in 44 searches, nine arrests and 13 pretrial detentions. Investigators found that the group built a network of shell companies and purchased luxury real estate and goods to conceal drug proceeds. Illegal financial brokers were a central component of the laundering operation, converting fiat currency into cryptocurrency and moving funds abroad.
Police froze assets of up to one billion reais — approximately $197 million — as part of the investigation.
The Brazilian operation follows a May report from the U.S. Treasury, which sanctioned six Ethereum addresses linked to the financial network of the Sinaloa cartel. Those wallets were used to convert drug proceeds into digital assets — illustrating a pattern that is becoming standard practice across major drug trafficking organisations globally. Cryptocurrency's speed, cross-border accessibility and, in some implementations, pseudonymity make it an increasingly attractive tool for converting illicit cash into harder-to-trace digital value.
Hackers Knocked Out Automation at 30+ Minnesota Water Utilities
On July 26 and 27, unknown hackers targeted the operational technology systems of more than 30 public water utilities across Minnesota, prompting the state's IT services agency — MNIT — to urgently activate cybersecurity protocols statewide.
In the city of Braham, a water treatment plant shut down entirely. Operations resumed approximately three hours later, with local authorities confirming the outage was caused by a targeted attack on computer control systems. Equipment in other counties also malfunctioned during the same period, forcing staff to execute contingency plans and switch pumps and filters to manual control.
MNIT confirmed the incident did not affect water quality and stated it is working with the FBI and the U.S. Cybersecurity and Infrastructure Security Agency to assess and remediate the attack's impact. The perpetrators have not been publicly identified.
The attack follows earlier warnings from U.S. authorities about mass attack campaigns by Iranian hackers targeting Rockwell Automation and Allen-Bradley programmable logic controllers — the industrial control systems used to manage water utilities and energy facilities. Whether this incident is connected to those campaigns has not been confirmed.
The Minnesota attack is a reminder that water infrastructure represents one of the most consequential targets in the critical infrastructure threat landscape. Unlike a data breach, an attack that disrupts water treatment or distribution has immediate public health implications — and the shift from automated to manual control, while effective as a contingency, exposes the degree to which modern utilities depend on the integrity of their digital systems.
Sources
Ukrainian Cyber Police report on Ukrainian Financial Academy fraud scheme, 2026. Brazilian Federal Police official statement on drug syndicate dismantlement, São Paulo, 2026. U.S. Treasury OFAC sanction of Sinaloa cartel Ethereum addresses, May 2026. MNIT cybersecurity incident response statement, July 27, 2026. FBI and CISA joint advisory on Iranian attacks on industrial control systems, April 2026. ForkLog cybersecurity digest, July 2026.